
SharePoint RCE CVE-2026-45659: Patch Before July 4 Deadline
SharePoint RCE CVE-2026-45659 is actively exploited by Storm-2603. Verify your SharePoint Server builds before CISA's July 4 patch deadline.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
16 results tagged ransomware

SharePoint RCE CVE-2026-45659 is actively exploited by Storm-2603. Verify your SharePoint Server builds before CISA's July 4 patch deadline.

Cisco Talos and Trend Micro confirm Qilin ransomware is using BYOVD to systematically disable 300+ EDR products before deploying ransomware. Here's the full attack chain and what to do about it.

CVE-2024-38094 is a deserialization remote code execution vulnerability in Microsoft SharePoint Server patched in July 2024. Site Owner-authenticated attackers can execute arbitrary code on the SharePoint server. Real-world campaigns chained it with a privilege escalation bug to achieve full domain compromise. CISA added it to the Known Exploited Vulnerabilities catalog in October 2024.

CVE-2024-37085 is an authentication bypass (CVSS 6.8) in VMware ESXi that allows a domain user who is a member of an Active Directory group named 'ESX Admins' to gain full administrative access to the ESXi hypervisor, regardless of whether that group was explicitly configured for ESXi access. Exploited by at least five ransomware groups (Black Basta, Akira, Medusa, RansomHub, and Scattered Spider) to target ESXi hosts directly, encrypting VM storage files and achieving mass disruption across virtualised environments.

CVE-2024-4577 is a critical PHP argument injection flaw affecting Windows servers running PHP in CGI mode. A Unicode best-fit character mapping quirk allowed attackers to bypass the CVE-2012-1823 patch and execute arbitrary OS commands without authentication. TellYouThePass ransomware operators weaponized it within hours of the June 2024 PoC release. CVSS 9.8.

CVE-2024-1709 is a CVSS 10.0 authentication bypass in ConnectWise ScreenConnect (< 23.9.8). An extra trailing slash in the URL path bypasses authentication middleware, allowing an unauthenticated attacker to execute the setup wizard and create a new administrator account. Exploited by LockBit, Black Basta, and multiple ransomware groups within 48 hours of disclosure. Affects all ScreenConnect on-premises deployments below version 23.9.8.

CVE-2023-46604 is a CVSS 10.0 deserialization / remote class loading vulnerability in Apache ActiveMQ's OpenWire protocol. An unauthenticated attacker sends a specially crafted ClassInfo message to port 61616, causing the broker to load and execute a Java class from an attacker-controlled HTTP server. Active exploitation by HelloKitty ransomware and Kinsing cryptominer began within days of the advisory. Affects ActiveMQ versions up to 5.15.16, 5.16.7, 5.17.6, and 5.18.3.

CVE-2023-34362 is a critical SQL injection vulnerability in Progress MOVEit Transfer that enables unauthenticated remote code execution. Exploited as a zero-day by the CLOP ransomware group beginning May 27, 2023, it was used to breach over 1,000 organizations simultaneously through data exfiltration without encryption. Victims include the US Department of Energy, Shell, British Airways, the BBC, Maximus, and hundreds more.

CVE-2023-28252 is a zero-day elevation of privilege vulnerability in the Windows Common Log File System (CLFS) kernel driver. A low-privileged attacker exploits a flaw in CLFS log file parsing to escalate to SYSTEM privileges. Discovered being actively used by the Nokoyawa ransomware gang as part of their pre-ransomware deployment privilege escalation chain. Patched on April 11, 2023 Patch Tuesday as a zero-day. CVSS 7.8.

CVE-2023-0669 is a pre-authentication remote code execution vulnerability in Fortra GoAnywhere MFT (Managed File Transfer). The Cl0p ransomware group exploited it as a zero-day for approximately 10 days before any advisory was published, claiming over 130 victim organisations. The vulnerability allows unauthenticated attackers to execute commands on the GoAnywhere server via a Java deserialization attack against the administrative console. Affected versions: GoAnywhere MFT prior to 7.1.2.

CVE-2022-26134 is a critical OGNL injection vulnerability in Atlassian Confluence Server and Data Center, enabling unauthenticated remote code execution. Disclosed as a zero-day on June 2, 2022 with active exploitation already confirmed, this vulnerability scores 10.0 CVSS. Within hours of technical details becoming public, mass scanning and exploitation began across the internet.

CVE-2021-26084 is a server-side template injection vulnerability in Atlassian Confluence Server and Data Center. An unauthenticated attacker can inject OGNL expressions via query parameters, achieving remote code execution on the Confluence server. The vulnerability was exploited at mass scale within hours of public PoC release, with ransomware groups and nation-state actors among the first adopters.

CVE-2021-34473 is the first link in the ProxyShell exploit chain, three Microsoft Exchange Server vulnerabilities that together enable unauthenticated remote code execution. Chained with CVE-2021-34523 and CVE-2021-31207, an attacker can reach Exchange's backend PowerShell endpoint without credentials, impersonate any mailbox user, and write arbitrary files to Exchange's web root to deploy a web shell.

CVE-2021-27101 is a critical SQL injection vulnerability in Accellion FTA (File Transfer Appliance) that allows unauthenticated remote code execution. Exploited by the CLOP ransomware group beginning in December 2020, the vulnerability was used to steal sensitive files from over 100 organizations including government agencies, universities, law firms, and financial institutions, without deploying ransomware encryption.
CVE-2020-14882 is a critical authentication bypass in the Oracle WebLogic Server web-based administration console. Chained with CVE-2020-14883, it enables unauthenticated remote code execution on one of the most widely deployed Java EE application servers in enterprise environments. Exploitation began within days of Oracle's October 2020 Critical Patch Update and was adopted by nation-state actors and ransomware operators.

CVE-2019-11510 is a pre-authentication arbitrary file read vulnerability in Pulse Connect Secure VPN appliances. An unauthenticated attacker can retrieve the VPN's configuration file and stored credentials, including plaintext passwords and cached Active Directory credentials, from any affected device reachable on the internet. Widely exploited by ransomware groups, APTs, and credential brokers.